Microsoft unveiled its first cybersecurity-specialized artificial intelligence model on Monday at an event in San Francisco, alongside a new agentic security platform called Project Perception, as the company pushes deeper into AI-driven enterprise defense. The company claims the system outperforms rival offerings from Anthropic and OpenAI on a widely used security benchmark while cutting operational costs roughly in half.
The model, named MAI-Cyber-1-Flash, is designed to handle routine vulnerability detection and remediation work inside Microsoft’s MDASH multi-agent harness, leaving more complex tasks to OpenAI’s GPT-5.4. Microsoft says the pairing scored 96 percent on the CyberGym benchmark, which measures how well AI systems identify vulnerabilities in large codebases, putting it 12 percentage points above Anthropic’s Mythos. The company also claims the configuration costs 50 percent less than its current MDASH production setup.
“We have world-leading performance at 50% of the cost,” Mustafa Suleyman, chief executive of Microsoft AI, said at the event, according to CNBC.
MAI-Cyber-1-Flash is derived from Microsoft’s MAI-Thinking-1 reasoning model, one of seven in-house models the company introduced in June. Microsoft says the cybersecurity model was built entirely in-house and draws on more than 100 trillion daily security signals spanning identity, endpoint, cloud, and network data. The company has positioned the model as a way to reduce reliance on outside providers, including OpenAI, even as it continues to use GPT-5.4 for the roughly 10 percent of tasks that require more capable reasoning.
Alongside the model, Microsoft introduced Project Perception, an agentic security system that coordinates three classes of specialized agents. Red team agents simulate how adversaries might move through a system, blue team agents identify and prioritize active threats, and green team agents execute remediation steps to close defensive gaps. The platform enters public preview on August 3 and will initially be available through Microsoft Defender.
Hayete Gallot, Microsoft’s executive vice president of security, described the platform in a blog post as giving enterprises the means to “defend against AI with AI at the scale and speed that the attackers have,” according to TechCrunch. Gallot returned to Microsoft in February to lead the security division.
Dave Weston, the lead engineer for Project Perception, told TechCrunch that the platform collapses work that previously consumed hours across multiple security specialists. “We’ve gone from this taking hours and hours of manual work from multiple specialized folks across the security organization , appsec hunters, remediation engineers, you name it , and in minutes, we have a fix for all of this,” Weston said.
Microsoft has not disclosed pricing for Project Perception, though the company says it will use consumption-based billing measured in security compute units. The more intensive the task, the more units an agent consumes.
The launch places Microsoft in direct competition with Anthropic’s Mythos, which reached a limited set of partners through a program called Glasswing, and OpenAI’s own cybersecurity offering, which debuted in May under a program called Daybreak. Microsoft last reported its cybersecurity revenue in 2023, stating it exceeded $20 billion annually, and has not provided an updated figure since.
It remains unclear how the new tools will perform outside benchmark conditions. Microsoft says MAI-Cyber-1-Flash was evaluated by its internal AI Red Team and independently assessed by a third party, though the company did not name the external evaluator.